Loading dump 1. Parsing dump 1. Loading dump 2. Parsing dump 2. Comparing the two dumps. Comparsion result: CRE HKEY_CLASSES_ROOT\ActiveXCtrl CRE HKEY_CLASSES_ROOT\ActiveXCtrl\ CRE HKEY_CLASSES_ROOT\ActiveXCtrl\CLSID CRE HKEY_CLASSES_ROOT\ActiveXCtrl\CLSID\ CRE HKEY_CLASSES_ROOT\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC} CRE HKEY_CLASSES_ROOT\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\ CRE HKEY_CLASSES_ROOT\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\InprocServer32 CRE HKEY_CLASSES_ROOT\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\InprocServer32\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Control CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Control\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32 CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32\ThreadingModel CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\1 CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\1\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ProgID CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ProgID\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ToolboxBitmap32 CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ToolboxBitmap32\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\TypeLib CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\TypeLib\ CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Version CRE HKEY_CLASSES_ROOT\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Version\ CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50} CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\ CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\IDEx CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\ CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\{00021492-0000-0000-C000-000000000046} CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\{00021492-0000-0000-C000-000000000046}\ CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32 CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32\ CRE HKEY_CLASSES_ROOT\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32\ThreadingModel CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7} CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\ CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\IDEx CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\ CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\{00021492-0000-0000-C000-000000000046} CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}\ CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32 CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32\ CRE HKEY_CLASSES_ROOT\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32\ThreadingModel CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8} CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid32 CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid32\ CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid\ CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib\ CRE HKEY_CLASSES_ROOT\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib\Version CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67} CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid32 CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid32\ CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid\ CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib\ CRE HKEY_CLASSES_ROOT\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib\Version CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42} CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0 CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\ CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0 CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0\win32 CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0\win32\ CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\FLAGS CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\FLAGS\ CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\HELPDIR CRE HKEY_CLASSES_ROOT\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\HELPDIR\ CRE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AddToFavoritesExpanded CRE HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Save Directory CRE HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\b CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com\MRUList CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com\a CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm\MRUList CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm\a CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\MRUList CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\a CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\b CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\c CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz\Days between clean up CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList\MRUList CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList\a CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList\b CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm\0 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm\MRUListEx CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\0 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\1 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\2 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\MRUListEx CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\11 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\12 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\13 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\14 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Rgurerny\havafgnyy.rkr CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\flfgrzfureybpx\qhzc_pbzcner_pbcl.ong CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Rgurerny\Havafgnyy Rgurerny.yax CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHAPCY:gvzrqngr.pcy CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheLimit CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheOptions CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CachePath CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CachePrefix CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheRepair CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheLimit CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheOptions CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CachePath CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CachePrefix CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheRepair CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3\MRUListEx CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3\NodeSlot CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\16 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\FolderType CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Address CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Buttons CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Col CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ColInfo CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\FFlags CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\FolderType CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\HotKey CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Links CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MaxPos800x600(1).x CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MaxPos800x600(1).y CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MinPos800x600(1).x CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MinPos800x600(1).y CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Mode CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Rev CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ScrollPos800x600(1).x CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ScrollPos800x600(1).y CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ShowCmd CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Sort CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\SortDir CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Status CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Vid CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WFlags CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).bottom CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).left CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).right CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).top CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@%SystemRoot%\system32\tourstart.exe,-2 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@%SystemRoot%\system32\xpsp1res.dll,-10078 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\bckgres.dll,-1212 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\chkrres.dll,-1212 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\hrtzres.dll,-1212 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\rvseres.dll,-1212 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\shvlres.dll,-1212 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\System32\comres.dll,-661 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\System32\mstsc.exe,-4000 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\compatUI.dll,-115 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\hnetwiz.dll,-3085 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\mshearts.exe,-413 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\netshell.dll,-1010 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\netshell.dll,-1200 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\notepad.exe,-469 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\restore\rstrui.exe,-2048 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\spider.exe,-56 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\usmt\migwiz.exe,-202 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@explorer.exe,-7004 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@explorer.exe,-7005 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-12691 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-12693 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21760 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21762 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21768 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21772 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21788 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22016 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22017 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22018 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22019 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22021 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22022 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22023 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22025 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22026 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22027 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22029 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22030 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22031 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22040 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22041 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22045 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22052 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22054 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22055 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22057 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22058 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22059 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22060 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22061 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22062 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22063 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22065 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22066 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22067 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22069 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31254 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31256 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31258 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31262 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31292 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31317 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31325 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31380 CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\Roger\LOKALA~1\Temp\A~NSISu_.exe CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\Roger\LOKALA~1\Temp\nsh_115.exe CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program\hjt\HijackThis.exe CRE HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\System32\taskmgr.exe CRE HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveXCtrl CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveXCtrl\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveXCtrl\CLSID CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveXCtrl\CLSID\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\InprocServer32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BFADCE2-1141-4B81-8878-49AF625F0FDC}\InprocServer32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Control CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Control\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InprocServer32\ThreadingModel CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\1 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\MiscStatus\1\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ProgID CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ProgID\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ToolboxBitmap32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\ToolboxBitmap32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\TypeLib CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\TypeLib\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Version CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Version\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\IDEx CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\{00021492-0000-0000-C000-000000000046} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\Implemented Categories\{00021492-0000-0000-C000-000000000046}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50}\InprocServer32\ThreadingModel CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\IDEx CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\{00021492-0000-0000-C000-000000000046} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0A54996-76FC-4471-9E03-41B60757ECE7}\InprocServer32\ThreadingModel CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\ProxyStubClsid\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{980AD470-04EA-4D1D-BD26-E178B7BDA6D8}\TypeLib\Version CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\ProxyStubClsid\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD39937A-C583-4AAC-9332-8A3E44988A67}\TypeLib\Version CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0\win32 CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\0\win32\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\FLAGS CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\FLAGS\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\HELPDIR CRE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE5AC3D6-6F43-4047-AF0A-D66FC2CF8F42}\1.0\HELPDIR\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Contains CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Contains\Files CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Contains\Files\C:\WINDOWS\Downloaded Program Files\ActiveX.ocx CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\DownloadInformation CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\DownloadInformation\CODEBASE CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InstalledVersion CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InstalledVersion\ CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\InstalledVersion\LastModified CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\Installer CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}\SystemComponent CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\Asynchronous CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\DllName CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\Impersonate CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\Logoff CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\Logon CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer\Shutdown CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\Asynchronous CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\DllName CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\Impersonate CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\Logoff CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\Logon CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls\Shutdown CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ActiveX.ocx CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ActiveX.ocx\.Owner CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ActiveX.ocx\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\ActiveX.ocx CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{63D66F1D-108C-4AFE-A298-C8B19CAE9B50} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A0A54996-76FC-4471-9E03-41B60757ECE7} CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\DisplayIcon CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\DisplayName CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\DisplayVersion CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\Publisher CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\URLInfoAbout CRE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis\UninstallString CRE HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\PendingFileRenameOperations CRE HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Internet Explorer\Main\AddToFavoritesExpanded CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Internet Explorer\Main\Save Directory CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\b CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com\MRUList CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\com\a CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm\MRUList CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm\a CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\MRUList CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\a CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\b CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log\c CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz\Days between clean up CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList\MRUList CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList\a CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList\b CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm\0 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.htm\MRUListEx CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\0 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\1 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\2 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.log\MRUListEx CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\11 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\12 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\13 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\14 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Rgurerny\havafgnyy.rkr CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\flfgrzfureybpx\qhzc_pbzcner_pbcl.ong CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Rgurerny\Havafgnyy Rgurerny.yax CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHAPCY:gvzrqngr.pcy CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheLimit CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheOptions CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CachePath CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CachePrefix CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050620\CacheRepair CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheLimit CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheOptions CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CachePath CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CachePrefix CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005063020050701\CacheRepair CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3\MRUListEx CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\3\NodeSlot CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\16 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\FolderType CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Address CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Buttons CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Col CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ColInfo CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\FFlags CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\FolderType CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\HotKey CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Links CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MaxPos800x600(1).x CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MaxPos800x600(1).y CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MinPos800x600(1).x CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\MinPos800x600(1).y CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Mode CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Rev CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ScrollPos800x600(1).x CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ScrollPos800x600(1).y CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\ShowCmd CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Sort CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\SortDir CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Status CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\Vid CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WFlags CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).bottom CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).left CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).right CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell\WinPos800x600(1).top CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@%SystemRoot%\system32\tourstart.exe,-2 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@%SystemRoot%\system32\xpsp1res.dll,-10078 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\bckgres.dll,-1212 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\chkrres.dll,-1212 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\hrtzres.dll,-1212 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\rvseres.dll,-1212 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\Program\MSNGAM~1\Windows\shvlres.dll,-1212 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\System32\comres.dll,-661 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\System32\mstsc.exe,-4000 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\compatUI.dll,-115 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\hnetwiz.dll,-3085 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\mshearts.exe,-413 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\netshell.dll,-1010 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\netshell.dll,-1200 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\notepad.exe,-469 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\restore\rstrui.exe,-2048 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\spider.exe,-56 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@C:\WINDOWS\system32\usmt\migwiz.exe,-202 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@explorer.exe,-7004 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@explorer.exe,-7005 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-12691 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-12693 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21760 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21762 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21768 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21772 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-21788 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22016 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22017 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22018 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22019 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22021 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22022 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22023 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22025 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22026 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22027 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22029 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22030 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22031 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22040 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22041 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22045 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22052 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22054 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22055 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22057 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22058 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22059 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22060 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22061 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22062 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22063 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22065 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22066 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22067 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-22069 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31254 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31256 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31258 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31262 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31292 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31317 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31325 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31380 CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\Roger\LOKALA~1\Temp\A~NSISu_.exe CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\Roger\LOKALA~1\Temp\nsh_115.exe CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program\hjt\HijackThis.exe CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\System32\taskmgr.exe CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs CRE HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates CRE c:\Documents and Settings\Roger\Cookies\roger@belnk[1].txt CRE c:\Documents and Settings\Roger\Cookies\roger@dist.belnk[2].txt CRE c:\Documents and Settings\Roger\Cookies\roger@iowrestling[1].txt CRE c:\Documents and Settings\Roger\Cookies\roger@targetnet[1].txt CRE c:\Documents and Settings\Roger\Lokala inställningar\Temp\A~NSISu_.exe CRE c:\Documents and Settings\Roger\Lokala inställningar\Temp\nsh_115.exe CRE c:\Documents and Settings\Roger\Lokala inställningar\Temp\~DFF557.tmp CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\003366[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\ActiveX[1].ocx CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\STATS15[1].CHM CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\adv3[1].jpg CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\id=adami79&opt=hhn&rw=468&rh=60&cv=220&uid=1[1].htm CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\startpage1[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\stats15[1].htm CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ\terms[1].html CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\ActiveX[1].htm CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\CA0TI5A7.HTM CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\ThawteCodeSigningCA[1].crl CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\adv4[1].jpg CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\bookmark1[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\eula[1].htm CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\insider8[1].jpg CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ\inst15[1].exe CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\1-blinking[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\ThawtePremiumServerCA[1].crl CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\a[1].php CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\contact1[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\iowrestling[1].htm CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\molly7[1].jpg CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV\prohosters[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\1167[1] CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\468X80banner[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\4A79AD[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\Installer[1].exe CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\copyright1[1].gif CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\enteriow[1].jpg CRE c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB\nsh_115[1].exe CRE c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061320050620 CRE c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061320050620\index.dat CRE c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005063020050701 CRE c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005063020050701\index.dat CRE c:\Documents and Settings\Roger\Mina dokument\hijackthis1.log CRE c:\Documents and Settings\Roger\Mina dokument\hijackthis2.log CRE c:\Documents and Settings\Roger\Mina dokument\hijackthis3.log CRE c:\Documents and Settings\Roger\Mina dokument\terms-icannews.com.htm CRE c:\Documents and Settings\Roger\Mina dokument\terms-newsh.com-mfc.htm CRE c:\Documents and Settings\Roger\Recent\hijackthis1.log.lnk CRE c:\Documents and Settings\Roger\Recent\hijackthis2.log.lnk CRE c:\Documents and Settings\Roger\Recent\hijackthis3.log.lnk CRE c:\Documents and Settings\Roger\Recent\terms-newsh.com-mfc.htm.lnk CRE c:\Program\Ethereal\network-log-plain.txt CRE c:\Program\Ethereal\network-log.txt CRE c:\Program\systemsherlock\before.dat CRE c:\Program\systemsherlock\network-log-urls.txt CRE c:\Temp CRE c:\Temp\Installer.exe CRE c:\WINDOWS\Downloaded Program Files\ActiveX.ocx CRE c:\WINDOWS\Prefetch\A~NSISU_.EXE-1E338B64.pf CRE c:\WINDOWS\Prefetch\GREP.EXE-0EA4342B.pf CRE c:\WINDOWS\Prefetch\INSTALLER.EXE-0870C3CA.pf CRE c:\WINDOWS\Prefetch\NSH_115.EXE-081E5C26.pf CRE c:\WINDOWS\Prefetch\RUNDLL32.EXE-32240B45.pf CRE c:\WINDOWS\Prefetch\RUNDLL32.EXE-492F8754.pf CRE c:\WINDOWS\Prefetch\UNINSTALL.EXE-2E9623DD.pf CRE c:\WINDOWS\Prefetch\UPDINST.EXE-01B81ED6.pf CRE c:\WINDOWS\Prefetch\WMPLAYER.EXE-0003D43A.pf CRE c:\WINDOWS\system32\sgftpub.dll CRE c:\WINDOWS\system32\stmpsnap.dll CRE c:\WINDOWS\system\UpdInst.exe DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614 DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheLimit DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheOptions DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CachePath DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CachePrefix DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheRepair DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619 DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheLimit DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheOptions DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CachePath DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CachePrefix DEL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheRepair DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614 DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheLimit DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheOptions DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CachePath DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CachePrefix DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061320050614\CacheRepair DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619 DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheLimit DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheOptions DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CachePath DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CachePrefix DEL HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012005061820050619\CacheRepair DEL c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061320050614 DEL c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061320050614\index.dat DEL c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061820050619 DEL c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\MSHist012005061820050619\index.dat DEL c:\WINDOWS\system32\CatRoot2\tmp.edb MOD HKEY_CLASSES_ROOT\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}\409 MOD HKEY_CLASSES_ROOT\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}\409 MOD HKEY_CURRENT_USER\SessionInformation\ProgramCount MOD HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\GeneralFlags MOD HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\MRUList MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\a MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\MRUList MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\d MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\e MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\f MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\g MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\h MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz\Last used time MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum\Implementing MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum\Implementing MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList\MRUList MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c906e-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c906f-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c9071-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\MRUListEx MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\StartMenu_Balloon_Time MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop\TaskbarWinXP MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\IconStreams MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\PastIconsStream MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count\HRZR_PGYFRFFVBA MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Rgurerny\_ehargu.ong MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Vagrearg Rkcybere\vrkcyber.rkr MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\uwg\UvwnpxGuvf.rkr MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\JVAQBJF\Flfgrz32\ABGRCNQ.RKR MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Rgurerny MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:::{2559N1S4-21Q7-11Q4-OQNS-00P04S60O9S0} MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHAPCY MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_PGYFRFFVBA MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\MRUListEx MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\MinPos800x600(1).x MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\MinPos800x600(1).y MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\ScrollPos800x600(1).y MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\ShowCmd MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\WFlags MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).bottom MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).left MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).right MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).top MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell\ShowCmd MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell\WFlags MOD HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop\ColInfo MOD HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}\409 MOD HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}\409 MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0048F8D37B153F6EA2798C323EF4F318A5624A9E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0483ED3399AC3608058722EDBC5E4600E3BEF9D7\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\049811056AFE9FD0F5BE01685AACE6A5D1C4454C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F55E8839BAC30728BE7108EDE7B0BB0D3298224\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\209900B63D955728140CD13622D8C687A4EB0085\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\216B2A29E62A00CE820146D8244141B92511B279\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\23E594945195F2414803B4D564D2A3A3F5D88B8C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\24A40A1F573643A67F0A4B0749F6A22BF28ABB6B\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\24BA6D6C8A5B5837A48DB5FAE919EA675C94D217\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\273EE12457FDC4F90C55E82B56167F62F532E547\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\284F55C41A1A7A3F8328D4C262FB376ED6096F24\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2F173F7DE99667AFA57AF80AA2D1B12FAC830338\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36863563FD5128C7BEA6F005CFE9B43668086CCE\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\394FF6850B06BE52E51856CC10E180E882B385CC\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4072BA31FEC351438480F62E6CB95508461EAB2F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\43DDB1FFF3B49B73831407F6BC8B975023D07C50\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\43F9B110D5BAFD48225231B0D0082B372FEF9A54\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4463C531D7CCC1006794612BB656D3BF8257846F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47AFB915CDA26D82467B97FA42914468726138DD\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4B421F7515F6AE8A6ECEF97F6982A400A4D9224E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4BA7B9DDD68788E12FF852E1A024204BF286A8F6\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4C95A9902ABE0777CED18D6ACCC3372D2748381E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\54F9C163759F19045121A319F64C2D0555B7E073\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\58119F0E128287EA50FDD987456F4F78DCFAD6D4\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5B4E0EC28EBD8292A51782241281AD9FEEDD4E4C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D989CDB159611365165641B560FDBEA2AC23EF1\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5E5A168867BFFF00987D0B1DC2AB466C4264F956\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5E997CA5945AAB75FFD14804A974BF2AE1DFE7E1\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6372C49DA9FFF051B8B5C7D4E5AAE30384024B9C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6782AAE0EDEEE21A5839D3C0CD14680A4F60142A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\67EB337B684CEB0EC2B0760AB488278CDD9597DD\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\687EC17E0602E3CD3F7DFBD7E28D57A0199A3F44\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\688B6EB807E8EDA5C7B17C4393D0795F0FAE155F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\68ED18B309CD5291C0D3357C1D1141BF883866B1\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\69BD8CF49CD300FB592E1793CA556AF3ECAA35FB\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6A174570A916FBE84453EED3D070A1D8DA442829\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\720FC15DDC27D456D098FABF3CDD78D31EF5A8DA\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\74207441729CDD92EC7931D823108DC28192E2BB\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7639C71847E151B5C7EA01C758FBF12ABA298F7A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\78E9DD0650624DB9CB36B50767F209B843BE15B3\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7A74410FB0CD5C972A364B71BF031D88A6510E9E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7AC5FFF8DCBC5583176877073BF751735E9BD358\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7CA04FD8064C1CAA32A37AA94375038E8DF8DDC0\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E784A101C8265CC2DE1F16D47B440CAD90A1945\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\81968B3AEF1CDC70F5FA3269C292A3635BD123D3\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\838E30F77FDD14AA385ED145009C0E2236494FAA\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85A408C09C193E5D51587DCDD61330FD8CDE37BF\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\879F4BEE05DF98583BE360D633E70D3FFE9871AF\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8EB03FC3CF7BB292866268B751223DB5103405CB\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\9078C5A28F9A4325C2A7C73813CDFE13C20F934E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\90AEA26985FF14804C434952ECE9608477AF556F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\90DEDE9E4C4E9F6FD88617579DD391BC65A68964\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\96974CD6B663A7184526B1D648AD815CF51E801A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\99A69BE61AFE886B4D2B82007CB854FC317E1539\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\9BACF3B664EAC5A17BED08437C72E4ACDA12F7E7\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\9E6CEB179185A29EC6060CA53E1974AF94AF59D4\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\9FC796E8F8524F863AE1496D381242105F1B78F5\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A399F76F0CBF4C9DA55E4AC24E8960984B2905B6\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A3E31E20B2E46A328520472D0CDE9523E7260C6D\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A5EC73D48C34FCBEF1005AEB85843524BBFAB727\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AB48F333DB04ABB9C072DA5B0CC1D057F0369B46\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\ACED5F6553FD25CE015F1F7A483B6A749F6178C6\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B172B1A56D95F91FE50287E14D37EA6A4463768A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B19DD096DCD4E3E0FD676885505A672C438D4E9C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B3EAC44776C9C81CEAF29D95B6CCA0081B67EC9D\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B5D303BF8682E152919D83F184ED05F1DCE5370C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B6AF5BE5F878A00114C3D7FEF8C775C34CCD17B6\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B72FFF92D2CE43DE0A8D4C548C503726A81E2B93\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\BC9219DDC98E14BF1A781F6E280B04C27F902712\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABB51672400588E6419F1D40878D0403AA20264\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CFDEFE102FDA05BBE4C78D2E4423589005B2571D\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CFF360F524CB20F1FEAD89006F7F586A285B2D5B\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CFF810FB2C4FFC0156BFE1E1FABCB418C68D31C5\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D29F6C98BEFC6D986521543EE8BE56CEBC288CF3\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D2EDF88B41B6FE01461D6E2834EC7C8F6C77721E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DA40188B9189A3EDEEAEDA97FE2F9DF5B7D18A41\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DBAC3C7AA4254DA1AA5CAAD68468CB88EEDDEEA8\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E392512F0ACFF505DFF6DE067F7537E165EA574B\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E4554333CA390E128B8BF81D90B70F4002D1D6E9\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E5DF743CB601C49B9843DCAB8CE86A81109FE48E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EBBC0E2D020CA69B222C2BFFD203CB8BF5A82766\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EF2DACCBEABB682D32CE4ABD6CB90025236C07BC\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F44095C238AC73FC4F77BF8F98DF70F8F091BC52\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F88015D3F98479E1DA553D24FD42BA3F43886AEF\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\063DA67748F0ECCC690D319BCDCD0E72AC8D48D5\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\12519AE9CD777A560184F1FBD54215222E95E71F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\189271E573FED295A8C130EAF357A20C4A9F115E\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\2D69A20EC4F0CD19037FD6D6246B1EE0EC41BA22\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\7B02312BACC59EC388FEAE12FD277F6A9FB4FAC1\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\9F025D9F58711A605EB0694B0E8BC0CA4F25FD6F\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\BA9E3C32562A67128CAABD4AB0C500BEE1D0C256\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\E5215D3460C2C20BBE2D9FE5FB665DAA2C0E225C\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\F6357239B7C39725BD8000646E4A0D18EBCE4CFA\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FE622EA7B33CA46519AB39736A66B8F6E41FF157\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob MOD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent\ MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dhcp\Parameters\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F} MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\LeaseObtainedTime MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\LeaseTerminatesTime MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\T1 MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\T2 MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\LeaseObtainedTime MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\LeaseTerminatesTime MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\T1 MOD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\T2 MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent\ MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F} MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\LeaseObtainedTime MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\LeaseTerminatesTime MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\T1 MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\T2 MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\LeaseObtainedTime MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\LeaseTerminatesTime MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\T1 MOD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BC24B697-4C1E-4D3C-89B7-B171BA2A583F}\Parameters\Tcpip\T2 MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\SessionInformation\ProgramCount MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Internet Explorer\Desktop\Components\GeneralFlags MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Internet Explorer\Main\Window_Placement MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\MRUList MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\a MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\MRUList MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\d MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\e MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\f MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\g MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\h MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz\Last used time MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum\Implementing MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Enum\Implementing MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList\MRUList MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c906e-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c906f-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ba2c9071-d9f1-11d9-a20c-806d6172696f}\Generation MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\MRUListEx MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\StartMenu_Balloon_Time MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop\TaskbarWinXP MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\IconStreams MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\PastIconsStream MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count\HRZR_PGYFRFFVBA MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Rgurerny\_ehargu.ong MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\Vagrearg Rkcybere\vrkcyber.rkr MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebtenz\uwg\UvwnpxGuvf.rkr MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\JVAQBJF\Flfgrz32\ABGRCNQ.RKR MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Rgurerny MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:::{2559N1S4-21Q7-11Q4-OQNS-00P04S60O9S0} MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHAPCY MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_PGYFRFFVBA MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\MRUListEx MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\MinPos800x600(1).x MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\MinPos800x600(1).y MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\ScrollPos800x600(1).y MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\ShowCmd MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\15\Shell\WFlags MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).bottom MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).left MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).right MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell\WinPos800x600(1).top MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell\ShowCmd MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell\WFlags MOD HKEY_USERS\S-1-5-21-1229272821-413027322-839522115-1003\Software\Microsoft\Windows\Shell\Bags\1\Desktop\ColInfo MOD c:\ MOD c:\Documents and Settings\Roger\Application Data\Ethereal\recent MOD c:\Documents and Settings\Roger\Cookies MOD c:\Documents and Settings\Roger\Cookies\index.dat MOD c:\Documents and Settings\Roger\Lokala inställningar\Temp MOD c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\492F49EJ MOD c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\8XMJGLIZ MOD c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\C12FS9AV MOD c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\KHYB4HUB MOD c:\Documents and Settings\Roger\Lokala inställningar\Temporary Internet Files\Content.IE5\index.dat MOD c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5 MOD c:\Documents and Settings\Roger\Lokala inställningar\Tidigare\History.IE5\index.dat MOD c:\Documents and Settings\Roger\Mina dokument MOD c:\Documents and Settings\Roger\NTUSER.DAT.LOG MOD c:\Documents and Settings\Roger\Recent MOD c:\Program\Ethereal MOD c:\Program\Ethereal\snmp\mibs\.index MOD c:\Program\Windows Media Player\wmplayer.exe MOD c:\Program\hjt MOD c:\Program\systemsherlock MOD c:\Program\systemsherlock\dump_compare_copy.bat MOD c:\RECYCLER\S-1-5-21-1229272821-413027322-839522115-1003\INFO2 MOD c:\WINDOWS\Downloaded Program Files MOD c:\WINDOWS\Prefetch MOD c:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf MOD c:\WINDOWS\Prefetch\ETHEREAL.EXE-0D6AF674.pf MOD c:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf MOD c:\WINDOWS\Prefetch\HIJACKTHIS.EXE-06DDFE72.pf MOD c:\WINDOWS\Prefetch\IEXPLORE.EXE-350E1020.pf MOD c:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf MOD c:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf MOD c:\WINDOWS\Prefetch\SED.EXE-07C7F123.pf MOD c:\WINDOWS\Prefetch\SYSTEMSHERLOCK.EXE-3ABE9B82.pf MOD c:\WINDOWS\setupapi.log MOD c:\WINDOWS\system MOD c:\WINDOWS\system32 MOD c:\WINDOWS\system32\CatRoot2 MOD c:\WINDOWS\system32\CatRoot2\edb.chk MOD c:\WINDOWS\system32\CatRoot2\edb.log MOD c:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb MOD c:\WINDOWS\system32\config\default.LOG MOD c:\WINDOWS\system32\config\software MOD c:\WINDOWS\system32\config\software.LOG MOD c:\WINDOWS\system32\config\system.LOG MOD c:\WINDOWS\system32\wbem\Logs\wbemess.log Compare finished.